Week 32, 2026 — Aug 3 – Aug 9, 2026
Everything the 24 aggregated CERT, PSIRT and vulnerability-database feeds published in this ISO week, condensed: what was added to the CISA KEV catalog, which advisories matter most and which products were hit. Daily detail lives in the daily briefings.
Added to the CISA KEV catalog
- criticalCVE-2026-8037added 2026-08-07 · public exploit code
- criticalCVE-2026-63077added 2026-08-05 · CVSS 9.8 · public exploit code
- criticalCVE-2026-9198added 2026-08-04 · CVSS 9.8 · public exploit code
- criticalCVE-2026-18556added 2026-08-04 · CVSS 7.4 · public exploit code
- criticalCVE-2026-34486added 2026-08-04 · public exploit code
- criticalCVE-2026-18577added 2026-08-03 · CVSS 8.1 · public exploit code
Notable advisories
CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability
ABB Ability Zenon
[NEW] [high] IBM Langflow Desktop OSS: Multiple vulnerabilities
CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
CVE-2026-9198: IBM Langflow Code Injection Vulnerability
CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place
CISA Adds One Known Exploited Vulnerability to Catalog
[NEW] [high] Arista VeloCloud Orchestrator: Vulnerability enables execution of arbitrary code with root privileges
Most-affected products
Volume by source
Other weeks
Don't wait a week. The daily briefing lands in your inbox every morning after 06:00 UTC — subscribe free, or watch specific products for instant advisory alerts.